Published: 28/10/2006 Updated: 17/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Off-by-one error in the MIME Multipart dissector in Wireshark (formerly Ethereal) 0.10.1 up to and including 0.99.3 allows remote malicious users to cause a denial of service (crash) via certain vectors that trigger an assertion error related to unexpected length values.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.
Vulnerable Product Search on Vulmon Subscribe to Product

wireshark wireshark 0.7.9

wireshark wireshark 0.8.16

wireshark wireshark 0.10

wireshark wireshark 0.99.1

wireshark wireshark 0.99.2

wireshark wireshark 0.99.3

wireshark wireshark 0.9.10

wireshark wireshark 0.99

wireshark wireshark 0.10.13

wireshark wireshark 0.10.4

Vendor Advisories

Several remote vulnerabilities have been discovered in the Ethereal network scanner The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-4574 It was discovered that the MIME multipart dissector is vulnerable to denial of service caused by an off-by-one overflow CVE-2006-4805 It was discovered t ...
Debian Bug report logs - #396258 multiple wireshark security issues fixed in 0994 Package: wireshark; Maintainer for wireshark is Balint Reczey <rbalint@ubuntucom>; Source for wireshark is src:wireshark (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Mon, 30 Oct 2006 20:48:12 UTC Severity ...